Symantec IGA

 View Only
  • 1.  Set Identity Portal Delegation

    Posted Dec 04, 2019 10:12 PM
    Hi

    A couple of Questions about Delegation in Identity Portal:

    1. As the Delegation is done at the Portal level rather than IM level, how can we have the Approval Email set to the Delegatees as well as the Designated Approver.
    2. Is there anyway for the Delegations to be set via data feed/web service rather than manually be the user?


    Regards


  • 2.  RE: Set Identity Portal Delegation

    Broadcom Employee
    Posted Dec 05, 2019 11:09 AM
    We see no way to accomplish these out of the box. You might want to submit an enhancement request in the Ideation section.

    ------------------------------
    Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.

    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------



  • 3.  RE: Set Identity Portal Delegation
    Best Answer

    Posted Dec 05, 2019 10:55 PM
    Hi

    Looking at this further:

    1) It appears that (in 14.3 at least) IM gets it correct, and emails All Approvers (including delegatees)    So this is in fact covered 

    2) It appears t IP does adds a value to the attribute imDelegators (so, if userX specified that they want to delegate to userY, the imDelegators attribute for userY is updated to a value like "uid=userXeople,ou=im,ou=ca,o=com#%$1575378000000#%$1577019600000"  where the start and end date are include  in unix time format.

    3) There is a task  PortalPortal Change My Delegations that is used by Portal to do this update:  but it doesn't seem you can expose it via TEWS (?)

    It may not be too hard to create our own Task to do this, and expose via TEWS.

    Cheers